Quantcast
Channel: Forensic Focus Forums - Recent Topics
Viewing all articles
Browse latest Browse all 20107

Mobile Phone Forensics: FTK Mobile Phone Examiner

$
0
0
MPE+ is a completely standalone product and the physical extracted files can be viewed from within the product. I have not needed to use FTK to complete a job, but it is handy to have as a resource! Some of the features I enjoy in this product: Physical Extraction (my main product for physical) Ability to import images (E01, Yaffs, DD, Cellbrite etc) for analysis or verification Timeline Visualisation/Social Analysis Mount image to run malware analysis Built in parsers for Android, iOS, IPD & Itunes backup. Built in SQLite browser & Application one click support I am hopeful that AccessData will incorporate their Cerberus Malware tools into this program in the future for live malware analysis. MPE+ has come a long way in the last 2 years and I am personally pleased with the updates so far. The product is not perfect and I cannot answer to the lack of language support but when I have needed the support it has always been there. With the imminent merger of the e-discovery and investigation products in the next few months, AD will make it seamless to analyse AD1 images in all the products. The other tools I use for mobile are Blacklight and Oxygen Analyst. Disclaimer: I have not used UFED.

Viewing all articles
Browse latest Browse all 20107

Trending Articles